Legal
Privacy notice
1Who this notice covers
This notice explains how DeedLens, based in Abuja, handles personal data under the Nigeria Data Protection Act 2023. It covers this website, the pilot and demo request form, and the DeedLens workspace.
2Two roles
- Controller for account data. DeedLens decides how it uses the business contact details of people at customers and prospective customers, account and sign in records, audit logs and the details sent through the request form.
- Processor for customer documents. When a customer uploads the papers behind a deal, the personal data in them, such as the names of sellers, buyers and witnesses, ID numbers and addresses, belongs to the customer's matter. The customer is the controller, and DeedLens processes that data only on its instructions, under a data processing agreement that every customer signs.
3What DeedLens collects as controller
- From the request form: company name, CAC number, company type, your name and role, work email, phone, the states you work in, packs a month and any notes.
- From the workspace: your name, work email and role, sign in records, and the actions you take, which the audit log records.
- From the website: the network address a request comes from, used for security and to limit repeated requests. The website sets no advertising or tracking cookies. Signed in users get one cookie that keeps them signed in.
4Why, and on what basis
- To answer a request and open an account: steps taken at your request before a contract, and DeedLens's legitimate interest in opening accounts only for registered businesses.
- To provide the workspace: the contract with your company.
- To keep the service secure, including the audit log and limits on repeated requests: legitimate interests.
- To meet legal duties, such as keeping tax records: legal obligation.
5Customer documents
DeedLens processes customer documents only to provide the service: reading pages, extracting fields, running checks and producing reports. It does not sell them, does not share them outside the customer's workspace except with the sub processor named below, and does not use them to train models unless the customer gives a written opt in.
Each customer's records are kept apart, and one company can never read another company's matters. DeedLens staff open a workspace only to support the customer or to keep the service secure, under a duty of confidentiality.
6Where data is held
DeedLens is built to run on Microsoft Azure in South Africa North, the closest Azure region to Nigeria. Holding data there is a transfer outside Nigeria, which relies on the safeguards in Part VIII of the Act, such as standard contractual clauses.
On Azure, Microsoft acts as DeedLens's sub processor for hosting and for the AI services that read pages.
Scans and photos are read in the same region. Reading pages with a language model is off unless the customer agrees in writing: in this region Azure offers those models only as global deployments, which may process page text in other Azure regions while stored data stays where it is.
Sign in uses Microsoft Entra External ID. Microsoft holds the work email and sign in records it needs to send each one time code, in the data location it sets for the DeedLens sign in directory.
7How long data is kept
- Raw files uploaded to a matter (the originals, the page images and the text read from them): deleted 12 months after the matter closes, unless the customer sets a longer period.
- Findings and reports: kept with the matter while the customer's account is open, unless the customer deletes the matter sooner.
- Deleted files can be restored for about 30 days in case of a mistake, then they are gone for good. Database backups are kept for 14 days.
- Account data: kept while the account is open, then only as long as the law requires for tax and contract records.
- Request form details that do not lead to an account: deleted once they are no longer needed to answer the request.
8Security
Access to a workspace is limited to the people its owner invites, with roles that decide who can review findings and who can manage users, and a matter can be kept to named people. Every change and every sign in is recorded in an audit log whose events are chained, so a later change shows, and every file is hashed when it arrives, so a later swap is visible. The security page has more.
9Breaches
If a personal data breach is likely to put people's rights and freedoms at risk, DeedLens notifies the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and tells affected customers without undue delay so that they can meet their own duties.
10Your rights
Under the Act you can ask to be told how your data is used, to see it, to correct it, to have it deleted, to restrict or object to its use, to receive it in a portable form, and to withdraw consent where consent is the basis. You can also complain to the Nigeria Data Protection Commission.
If your data is in documents that a DeedLens customer uploaded, that customer is the controller, so contact them first. DeedLens helps its customers answer these requests.
11Children
DeedLens is a business service and is not meant for children.
12Changes to this notice
DeedLens updates this notice when its practices change, and tells account owners about material changes by email.
13Contact
Send privacy questions and requests to DeedLens through chinaza@deedlens.online.
